AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

European AI sovereignty certifications, especially SecNumCloud, include a unique 24% ownership cap to ensure legal control. However, this rule has significant limitations, raising concerns about actual sovereignty and compliance. The article explores these flaws and what they mean for providers and users.

European cybersecurity standards for AI and cloud services include a unique ownership control rule—the 24% cap—that aims to ensure legal sovereignty. However, experts warn that this rule alone may not guarantee actual control or immunity from foreign jurisdiction, raising questions about the effectiveness of current certification processes.

The SecNumCloud certification, issued by France’s ANSSI, is a government-backed qualification that requires providers to meet strict criteria, including EU legal domicile, data storage, and audited key custody. The key feature is the ownership cap: foreign companies cannot hold more than 24% of voting rights, or 39% collectively, to qualify. This arithmetic rule aims to prevent foreign control, but experts note it is a brutally difficult standard to meet, with only about a dozen providers holding valid certifications as of mid-2026.

While certifications like ISO 27001 and BSI C5 focus on security practices, they do not address jurisdictional immunity. SecNumCloud, by contrast, explicitly ties sovereignty to ownership and control, making it a unique but challenging benchmark. US-based hyperscalers, unable to meet the control requirements directly, have often created joint ventures to circumvent the rule, such as Thales-Google’s S3NS or Capgemini-Orange’s Bleu.

These arrangements demonstrate that the ownership rule can be manipulated, which raises concerns about its effectiveness in ensuring sovereignty. The certification’s reliance on a simple arithmetic cap does not fully address the complexities of control, especially when control is exercised through legal or operational arrangements.

At a glance
analysisWhen: developing, as of mid-2026
The developmentThe article examines the vulnerabilities of the 24% ownership rule in European AI sovereignty certification processes, highlighting its limitations and implications.

Implications of the 24% Control Limit on Sovereignty

The 24% ownership cap is central to European efforts to ensure legal sovereignty over data and AI services. However, experts warn that this arithmetic control measure can be bypassed through joint ventures and control arrangements, undermining the very purpose of the certification. This raises questions about whether the current standards truly guarantee immunity from foreign jurisdiction or merely provide a perception of control.

For European governments and organizations relying on these certifications, the flaws could mean continued exposure to legal risks under foreign laws like the CLOUD Act. For providers, the challenge is balancing compliance with sovereignty requirements while maintaining operational flexibility. Ultimately, this debate impacts trust in European certification schemes and the future of AI sovereignty in Europe.

Amazon

European AI sovereignty certification software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Evolution and Challenges of European Sovereignty Standards

European AI and cloud sovereignty standards have evolved amid concerns over foreign control and data security. The SecNumCloud certification, introduced in 2016 and now in referential version 3.2, is a key element of France’s Cloud au Centre doctrine, which mandates its use for sensitive public-sector data. It emphasizes legal sovereignty through strict criteria, including the ownership cap.

Other frameworks like ISO 27001 and BSI C5 focus on security practices but do not address legal jurisdiction. The 24% rule was introduced as a straightforward, arithmetic measure to prevent foreign control, but its simplicity has led to loopholes and creative arrangements by US and non-EU providers.

As of mid-2026, about nine to ten providers hold active SecNumCloud certifications, with several more in pipeline. The certification is increasingly mandated for vital sectors such as health, energy, and finance, making its robustness critical to European sovereignty efforts.

“Meeting the 24% control threshold is extremely difficult, especially for large, multinational providers, making joint ventures the only viable workaround.”

— A provider executive involved in certification

Amazon

SecNumCloud compliance tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unresolved Risks of Control Manipulation

It remains unclear how effectively the ownership cap prevents control circumvention via joint ventures or operational arrangements. Experts warn that providers can still exercise significant influence without exceeding the 24% threshold, potentially undermining sovereignty guarantees. The long-term robustness of SecNumCloud in preventing foreign control is an open question, especially as providers develop creative legal structures.

Amazon

AI control and ownership verification software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Future Developments in European AI Sovereignty Standards

Regulators and policymakers are likely to revisit the ownership control rules and tighten oversight to close loopholes. The European Commission may introduce more nuanced control measures or additional audits to verify actual influence. Meanwhile, more providers are expected to seek SecNumCloud certification, especially as the standards become mandatory for critical sectors. The debate over sovereignty versus operational flexibility will continue to shape Europe’s AI regulation landscape.

Amazon

cybersecurity certification for cloud providers

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Why is the 24% ownership rule considered a weakness?

The rule is a simple arithmetic cap that can be bypassed through joint ventures or operational control, which may still allow foreign influence and undermine sovereignty.

How does SecNumCloud differ from other certifications?

SecNumCloud is a government-backed qualification that explicitly ties sovereignty to ownership and control, including legal domicile and immunity from non-EU laws, making it more stringent than security-focused standards like ISO 27001.

Can US companies meet SecNumCloud requirements directly?

Generally no, because US companies cannot meet the ownership control restrictions directly. They often create joint ventures or control arrangements to comply with the 24% rule.

What are the implications for European data sovereignty?

The flaws in the control rule suggest that current standards may not fully guarantee immunity from foreign jurisdiction, raising concerns about true sovereignty in European AI and cloud services.

Source: ThorstenMeyerAI.com

You May Also Like

The Growing Threat Of CVE-2026-8037 In LoadMaster: What Cybersecurity Pros Must Do

Security researchers warn of active exploitation of CVE-2026-8037 in Progress LoadMaster, urging immediate action for small and mid-sized organizations.

Smishing 101: Spot and Stop SMS Phishing

Ongoing SMS scams like smishing can catch you off guard—discover how to identify and prevent these deceptive messages before it’s too late.

COPPA Basics: A Parent’s Guide to Kids’ Privacy

Understanding COPPA is crucial for protecting your child’s privacy online; discover essential tips to keep your kids safe and informed.

Instructure strikes deal with hackers who breached it twice

Instructure, maker of Canvas, announced it has struck a deal with hackers who stole data and disrupted schools, after two breaches and extortion threats.